From: Dr. Stephen Henson Date: Wed, 25 May 2011 15:20:49 +0000 (+0000) Subject: PR: 2533 X-Git-Tag: OpenSSL-fips-2_0-rc1~388 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=3d52f1d52b813652c845887d17c69699a92086d7;p=oweals%2Fopenssl.git PR: 2533 Submitted by: Robin Seggelmann Reviewed by: steve Setting SSL_MODE_RELEASE_BUFFERS should be ignored for DTLS, but instead causes the program to crash. This is due to missing version checks and is fixed with this patch. --- diff --git a/ssl/s3_pkt.c b/ssl/s3_pkt.c index ee103cd242..d1a18ee276 100644 --- a/ssl/s3_pkt.c +++ b/ssl/s3_pkt.c @@ -247,7 +247,8 @@ int ssl3_read_n(SSL *s, int n, int max, int extend) if (i <= 0) { rb->left = left; - if (s->mode & SSL_MODE_RELEASE_BUFFERS) + if (s->mode & SSL_MODE_RELEASE_BUFFERS && + SSL_version(s) != DTLS1_VERSION && SSL_version(s) != DTLS1_BAD_VER) if (len+left == 0) ssl3_release_read_buffer(s); return(i); @@ -866,7 +867,8 @@ int ssl3_write_pending(SSL *s, int type, const unsigned char *buf, { wb->left=0; wb->offset+=i; - if (s->mode & SSL_MODE_RELEASE_BUFFERS) + if (s->mode & SSL_MODE_RELEASE_BUFFERS && + SSL_version(s) != DTLS1_VERSION && SSL_version(s) != DTLS1_BAD_VER) ssl3_release_write_buffer(s); s->rwstate=SSL_NOTHING; return(s->s3->wpend_ret);